KYKY Assurance / threat model first

Check.Limit.Decide.

KYKY documents the checks performed by each surface, the data those checks cover, and the conclusions they cannot establish. Controls reduce risk; they do not eliminate it.

01

The signed-record threat model

What does the check prove?

The public renderer confirms a record/controller signature match. It does not independently prove identity, handle history, or payment purpose.

Your device controller signs the canonical record KYKY registry serves the record and the controller named inside that record KYKY client checks signature/controller match Profile page checks before rendering signed record record served signature matches the named controller canonical value changed signature fails · nothing shown BOUNDARY / this check does not independently prove identity or handle-to-controller history Your deviceController signs canonical record signed record KYKY registryServes record and controllernamed inside that record record served Checking surfaces KYKY clientmatch checked Profile pagematch checked controller match checked CONTROLLER MATCHSupported fields may render canonical value changed SIGNATURE FAILEDNo address shown
THE CHECK ESTABLISHES Record ↔ named controller

The renderer checks that the displayed canonical record was signed by the controller named inside that record.

THE CHECK DOES NOT ESTABLISH Person, history, or purpose

It does not independently prove a real person, organization, handle history, payment purpose, or that a recipient is safe.

02

The transaction path

01COMPOSEDefine the intended action.
02SIMULATEWhere supported, surface effects.
03AUTHENTICATEConfirm on device or hardware signer.
04RE-CHECKDecode the signed payload.
05BROADCASTOnly after the applicable checks.

03 / Browser boundary

The website gets
no private exception.

A connected site can prepare a request. The browser extension retains the account permission, signing key, and final approval surface. KYKY’s own website receives no privileged signing exception.

Illustrative client structure based on the existing Chromium extension. Distribution links are shown only when officially configured.

04

Engineering practice

Tests

Automated tests cover wallet cryptography, signing, transaction, and record paths.

Conformance

Signing is held to golden vectors: known inputs, byte-exact expected outputs.

Internal adversarial review

Value-movement paths receive dedicated internal adversarial review.

Privacy as practice

No analytics or tracking SDKs are included in KYKY Wallet.

NO EXTERNAL AUDIT COMPLETED

The current review evidence is internal. No certification or audit badge is claimed.

V1 RECORD LIMIT

Public profiles withhold exact-case address families until a case-preserving record format exists.

PAYMENT LINKS

The web fails closed until complete app-equivalent v4 verification is implemented.

SUPPORT + DISCLOSURE

Monitored operational contacts remain a production release requirement.

Continue through KYKY

Understand the check before relying on it.

Explore the wallet, signed-name model, and public profile boundary.